<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Compiling of Data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116110#M30831</link>
    <description>&lt;P&gt;Thanks. I've give this one a try and see how things pan out. I've never used the "bucket" or "streamstats" so I'll have some new toys to play with.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Fri, 25 Oct 2013 21:37:12 GMT</pubDate>
    <dc:creator>albyva</dc:creator>
    <dc:date>2013-10-25T21:37:12Z</dc:date>
    <item>
      <title>Compiling of Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116108#M30829</link>
      <description>&lt;P&gt;Using this set of data:&lt;/P&gt;

&lt;H2&gt;Time    Host    Type    Packets&lt;/H2&gt;

&lt;P&gt;12:00   mothra  A       5&lt;BR /&gt;
12:05   mothra  A       6&lt;BR /&gt;
12:10   mothra  A       7&lt;BR /&gt;
12:00   mothra  B       100&lt;BR /&gt;
12:05   mothra  B       200&lt;BR /&gt;
12:10   mothra  B       300&lt;/P&gt;

&lt;P&gt;I want to compile and calculate the data to come out like this:&lt;/P&gt;

&lt;H2&gt;Time    Host    Packet_Loss&lt;/H2&gt;

&lt;P&gt;12:10   mothra  0.03&lt;/P&gt;

&lt;P&gt;The problem I'm having is how do I gather up all of Type=A and Type=B so I can then run&lt;BR /&gt;
something like | eval=packetloss(typeA/typeB)   ?    I understand enough of splunk to gather&lt;BR /&gt;
up this data and all. My issue is getting everything under Type=A and Type=B combined so I &lt;BR /&gt;
can then run the math on it.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2013 19:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116108#M30829</guid>
      <dc:creator>albyva</dc:creator>
      <dc:date>2013-10-25T19:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Compiling of Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116109#M30830</link>
      <description>&lt;P&gt;There is probably a better search to use if I knew more about your data and use case , how many host types you are dealing with , what time buckets you want to calculate the ratios over etc...&lt;/P&gt;

&lt;P&gt;But anyhow , based purely on the data set above , this search worked. It should at least get you pointed in the right direction.I bucketed up into days , so the output is packet loss per day between those 2 host types. The streamstats command allows me to perform the ratio math on the current and previous event ie: host type A's packet sum and host type B's packet sum.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=main sourcetype=foo | bucket _time span=1d | stats sum(packets) as total_packets by host,type,_time | streamstats window=1 global=f current=f first(total_packets) as next_total_packets | eval packet_loss=next_total_packets/total_packets | table  _time host packet_loss | tail 1
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 25 Oct 2013 21:34:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116109#M30830</guid>
      <dc:creator>Damien_Dallimor</dc:creator>
      <dc:date>2013-10-25T21:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Compiling of Data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116110#M30831</link>
      <description>&lt;P&gt;Thanks. I've give this one a try and see how things pan out. I've never used the "bucket" or "streamstats" so I'll have some new toys to play with.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2013 21:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Compiling-of-Data/m-p/116110#M30831</guid>
      <dc:creator>albyva</dc:creator>
      <dc:date>2013-10-25T21:37:12Z</dc:date>
    </item>
  </channel>
</rss>

